Avatier

Attack outcomes

Double extortion

Also called: data extortion

Double extortion is a ransomware tactic in which attackers both encrypt a victim's systems and steal a copy of its data, then demand payment for two things: the decryption key and a promise not to publish the stolen files. Even an organization that restores from backups still faces the threat of a leak.

How it works

After getting in, the attackers quietly copy sensitive files to their own servers before deploying ransomware. The ransom note points to a leak site where they list the victim and post samples. If the victim refuses to pay, they release the data or sell it.

A real example

The FBI, CISA, HHS and MS-ISAC's Black Basta advisory said affiliates used common initial access techniques such as phishing and then employed a double-extortion model, both encrypting systems and exfiltrating data.

Source: #StopRansomware: Black Basta (AA24-131A) — Cybersecurity and Infrastructure Security Agency (CISA), 2024-05-10

How to stop it

Block the initial login with phishing-resistant MFA, limit how much data any one identity can read, and alert on large outbound transfers.

Related terms

Threat actors that use it

  • Akira

    Profile with government sources

  • Black Basta

    Profile with government sources

  • LockBit

    Profile with government sources

Sources

  1. #StopRansomware: Black Basta (AA24-131A) — Cybersecurity and Infrastructure Security Agency (CISA), 2024-05-10

Last reviewed Oct 2, 2026